CVE Explorer
CVE-2026-26187
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.HasPrefix() to verify that requested paths fall within the configured storage directory. This check was insufficient because it validated only the path prefix without requiring a path separator, allowing
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"lakeFS","vendor":"treeverse","versions":[{"status":"affected","version":"< 1.77.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/treeverse/lakeFS/commit/cbc106275357302a834280f133265dc39f1384ce","tags":["x_refsource_MISC"],"url":"https://github.com/treeverse/lakeFS/commit/cbc106275357302a834280f133265dc39f1384ce"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/references/1
{"name":"https://github.com/treeverse/lakeFS/releases/tag/v1.77.0","tags":["x_refsource_MISC"],"url":"https://github.com/treeverse/lakeFS/releases/tag/v1.77.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/references/2
{"name":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-699m-4v95-rmpm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/treeverse/lakeFS/security/advisories/GHSA-699m-4v95-rmpm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7a27701d13bd870d3edf8940eb9c74e5c3462f113e0905052123ded4670cd188 · sha256:f798a318c62c39bd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.